Home Malware Programs Trojans Java:Agent-KL

Java:Agent-KL

Posted: August 10, 2011

Java:Agent-KL is a JavaScript-based Trojan that can infect your PC by exploiting browser security holes. SpywareRemove.com malware research team has analyzed Java:Agent-KL and found that it shows behavior that's indicative of enabling other attacks, potentially including reducing your computer's security or installing other harmful applications such as spyware, scamware products or browser hijackers. Since Java:Agent-KL is a recent PC threat, you should be careful to keep all relevant security applications, as well as your browser and script-related packages up-to-date, to close any vulnerabilities that Java:Agent-KL might exploit. In rare cases, Java:Agent-KL may also be a harmless false positive, in which case no harm is done by either deleting Java:Agent-KL or leaving it alone.

The Surefire Way to Erect a Barrier Between Your PC and Possible Java:Agent-KL Attacks

As a JavaScript Trojan, Java:Agent-KL is incapable of attacking computers that don't have JavaScript installed. However, since JavaScript is required for many kinds of online content, an alternative means of protecting your PC against Java:Agent-KL is to keep your JavaScript package completely up-to-date. Patching Java will also close several vulnerabilities that are used by Java:Agent-KL and similar Trojans to infect your PC.

SpywareRemove.com malware research team finds most Java:Agent-KL infections to be the result of drive-by-download scripts that are coded, naturally, in Java. This scripts can be launched automatically by malicious websites or advertisements and install Java:Agent-KL without your consent or awareness. Since Java:Agent-KL infection symptoms can differ depending on the Java:Agent-KL variant and external instructions, you may be unable to detect Java:Agent-KL without the help of an appropriate PC security program.

Why You Shouldn't Take Chances with a Possible Java:Agent-KL Assault

Different versions of Java:Agent-KL may be capable to present some of the following malicious behavior:

  • Java:Agent-KL may act as a backdoor for your computer's security to allow remote criminals to attack and control the PC. Control can extend to stealing any private information, corrupting or destroying files or even forcing your PC to make self-destructive actions. Security attacks frequently can be seen in instances of unusually-altered network settings and changes that have been made to your firewall without your consent.
  • Java:Agent-KL may install other types of harmful programs. Popular Trojan payloads that SpywareRemove.com malware researchers have seen include scamware programs like Windows XP System Repair, browser hijackers like Findxplorer and other Trojans such as Trojan.Jifake, Trojan.IflardotC or Trojan-Clicker.Win32.Libie.le.
  • Java:Agent-KL may also be used to hijack your web browser and redirect you to harmful websites. Hijacks may occur spontaneously or when you perform a specific action, such as using a search engine. Java:Agent-KL hijacks are also capable of displaying fake error screens or embedding links into otherwise harmless content.

Despite these many risks, not all possible Java:Agent-KL infections are dangerous. SpywareRemove.com malware researchers have also found that Java:Agent-KL detections can occur as accidental false alerts, mostly triggered by components of various browser toolbars. Since these components can remain behind even if the toolbars themselves are uninstalled, you may want to use additional security software to double-check and make sure that Java:Agent-KL is a threat to your PC, before taking action. Java:Agent-KL false positives cause no harm to PC whether you choose to delete them or leave them alone.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%Windir%\svhoster.exe File name: %Windir%\svhoster.exe
File type: Executable File
Mime Type: unknown/exe

Registry Modifications

The following newly produced Registry Values are:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\..{RunKeys}net64 = "%Windir%\svhoster.exe" HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Loading...